Framework guide • Pakistan

SBP TRM: SBP Technology Risk Management (TRM) Framework for Payment Institutions

The SBP Technology Risk Management (TRM) Framework for Payment Institutions is the State Bank of Pakistan's baseline of technology, cyber and fraud-risk requirements for licensed payment institutions. These include EMIs, PSOs and PSPs licensed under the PS&EFT Act 2007. It was issued on 3 October 2025 through PSP&OD Circular No. 04 of 2025. Komply maps it as 111 requirements across five areas.

Last updated · By the Faseel compliance team · Not legal advice

SBP TRM at a glance

Issued by
State Bank of Pakistan — Payment Systems Policy & Oversight Department
Reference
PSP&OD Circular No. 04 of 2025, dated 3 October 2025
Applies to
Payment institutions licensed under the PS&EFT Act 2007: EMIs, PSOs, PSPs and other PIs
Structure
Governance (Sec 5), Technology & Cyber Risk (Sec 6), Digital Fraud (Sec 7), Outsourcing (Sec 8), DR & BC (Sec 9), plus pilot/commercial readiness (Annexure I)
Size
111 requirements across 25 sub-areas (as mapped in Komply)
ISO 27001 overlap
89 of 111 requirements map to an ISO/IEC 27001:2022 Annex A control

Who must comply with SBP TRM

Electronic Money Institutions (EMIs)

Wallet and e-money providers licensed by SBP.

Payment System Operators & Providers

PSOs and PSPs running payment rails, gateways and switching.

Pilot and commercial-stage PIs

Annexure I sets readiness requirements for institutions moving from pilot to commercial operations.

What SBP TRM requires

  • Board and senior-management oversight of technology risk, with approved policies and an independent technology audit.
  • Identity and access management, network security, data security, patch and change management.
  • Regular security testing (VAPT) and secure API management.
  • Incident response and reporting, threat intelligence, and event monitoring and detection.
  • Digital-fraud governance, prevention, detection, response and recovery.
  • Outsourcing and technology-service-provider oversight, including SBP's rights in agreements.
  • Disaster recovery and business continuity, with periodic DR testing.

SBP TRM domains and control counts

111 controls across 25 areas, as mapped in Komply.

SBP TRM domains with number of controls
DomainControls
Governance — Board & Senior Management4
Governance — Policies & Procedures6
Governance — Technology Audit3
Tech & Cyber — Inventory Management3
Tech & Cyber — Identity & Access Management8
Tech & Cyber — Network Security9
Tech & Cyber — Security Testing4
Tech & Cyber — Data Security4
Tech & Cyber — Patch & Change Management6
Tech & Cyber — Incident Response & Reporting4
Tech & Cyber — APIs5
Tech & Cyber — Threat Intelligence2
Tech & Cyber — Event Monitoring & Detection3
Digital Fraud — Governance4
Digital Fraud — Prevention8
Digital Fraud — Detection, Response & Recovery6
Outsourcing — Oversight2
Outsourcing — Arrangements4
Outsourcing — Agreement (SBP rights)3
Outsourcing — Third-Party Risk3
DR & BC — System Availability1
DR & BC — Business Continuity & DR5
DR & BC — DR Testing3
Annexure I — Pilot Stage Readiness7
Annexure I — Commercial Stage Readiness4
Total111

How SBP TRM maps to ISO 27001

89 of 111 TRM requirements map to ISO/IEC 27001:2022 Annex A, so ISO evidence can be reused. Payment-specific requirements such as fraud management, NADRA verification, SBP reporting and liability stand on their own.

Komply gives payment institutions the full TRM requirement set with ISO 27001 mappings, plus the evidence pack and VAPT your technology audit will ask for. Faseel's pentesters handle the security-testing requirements directly. See how Komply works.

SBP TRM FAQ

What is the SBP TRM Framework?

It is the State Bank of Pakistan's Technology Risk Management Framework for Payment Institutions, issued via PSP&OD Circular No. 04 of 2025 on 3 October 2025. It sets baseline requirements for governance, technology and cyber risk, digital-fraud management, outsourcing, and disaster recovery and business continuity.

Who does SBP TRM apply to?

Payment institutions licensed under the Payment Systems and Electronic Fund Transfers Act 2007. That includes Electronic Money Institutions (EMIs), Payment System Operators (PSOs), Payment Service Providers (PSPs) and other PIs. Implementation is expected to be proportionate to the institution's size, products and complexity.

Does SBP TRM require penetration testing?

Yes. The framework includes security-testing requirements (VAPT) under its Technology & Cyber Risk section, alongside API security, network security and event monitoring. Faseel performs these tests and maps the findings straight into the evidence Komply tracks.

How does SBP TRM relate to ISO 27001?

The two overlap substantially. 89 of the 111 requirements mapped in Komply have an equivalent ISO 27001:2022 Annex A control. Fraud, NADRA verification, SBP reporting and liability requirements are payment-specific and must be handled separately.

What is the compliance deadline for SBP TRM?

The timeline is set in PSP&OD Circular No. 04 of 2025. Check the circular and any follow-up SBP instructions for the date that applies to your licence category, because timelines can differ for new and existing institutions.

How does Komply help with SBP TRM?

Komply ships the full requirement set, drafts the policies, tracks evidence against each requirement, flags gaps, and exports an audit-ready package. Faseel adds the VAPT and technology-audit support.

Do ISO 27001 once. Prove SBP TRM too.

Komply maps 14 frameworks and 1,100+ controls into one control set. Start with a free gap assessment.